Atlas / Skills / foryourhealth111-pixel / Unsloth

UnslothBLOCK

skills/foryourhealth111-pixel/unsloth

Intelligent Skill routing and workflow orchestration for AI agents — +21.12 pp reward, −29.6% tokens on SkillsBench with DeepSeekV4Flash-VE.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
1.0.0
Hosts
—
License
Apache-2.0
Stars
3,607
01

Overview

Intelligent Skill routing and workflow orchestration for AI agents — +21.12 pp reward, −29.6% tokens on SkillsBench with DeepSeekV4Flash-VE.

Read from source at commit 5ff3ca429e5bOBSERVED · 2026-10-08
02

Install

Commands as the repository documents them. They are shown, not run.

pip install "unsloth[windows] @ git+https://github.com/unslothai/unsloth.git"
git clone https://github.com/ggml-org/llama.cpp
git clone https://github.com/ggml-org/llama.cpp
uv pip install -U vllm --pre --extra-index-url https://wheels.vllm.ai/nightly
git clone https://github.com/ggerganov/llama.cpp
pip install --upgrade torch==2.8.0 pytorch-triton-rocm torchvision torchaudio torchao==0.13.0 xformers --index-url https://download
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: unsloth
description: Expert guidance for fast fine-tuning with Unsloth - 2-5x faster training, 50-80% less memory, LoRA/QLoRA optimization
version: 1.0.0
author: Orchestra Research
license: MIT
tags: [Fine-Tuning, Unsloth, Fast Training, LoRA, QLoRA, Memory-Efficient, Optimization, Llama, Mistral, Gemma, Qwen]
dependencies: [unsloth, torch, transformers, trl, datasets, peft]
---

# Unsloth Skill

Comprehensive assistance with unsloth development, generated from official documentation.

## When to Use This Skill

This skill should be triggered when:
- Working with unsloth
- Asking about unsloth features or APIs
- Implementing unsloth solutions
- Debugging unsloth code
- Learning unsloth best practices

## Quick Reference

### Common Patterns

*Quick reference patterns will be added as you use the skill.*

## Reference Files

This skill includes comprehensive documentation in `references/`:

- **llms-txt.md** - Llms-Txt documentation

Use `view` to read specific reference files when detailed information is needed.

## Working with This Skill

### For Beginners
Start with the getting_started or tutorials reference files for foundational concepts.

### For Specific Features
Use the appropriate category reference file (api, guides, etc.) for detailed information.

### For Code Examples
The quick reference section above contains common patterns extracted from the official docs.

## Resources

### references/
Organized documentation extracted from official sources. These files contain:
- Detailed explanations
- Code examples with language annotations
- Links to original documentation
- Table of contents for quick navigation

### scripts/
Add helper scripts here for common automation tasks.

### assets/
Add templates, boilerplate, or example projects here.

## Notes

- This skill was automatically generated from official documentation
- Reference files preserve the structure and examples from source docs
- Code examples include language detection for better syntax highlighting
- Quick reference patterns are extracted from common usage examples in the docs

## Updating

To refresh this skill with updated documentation:
1. Re-run the scraper with the same configuration
2. The skill will be rebuilt with the latest information

<!-- Trigger re-upload 1763621536 -->
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (18)

HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
references/llms-txt.md:400
| **Gemma 3n** | E2B           | [link](https://huggingface.co/unsloth/gemma-3n-E2B-it-GGUF) | [link](https://huggingface.co/unsloth/gemma-3n-E2B-it-unsloth-bnb-4bit)      |
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
references/llms-txt.md:9050
* **DeepSeek-R1-Distill-Llama-8B** is a fine-tuned version of Llama-3.1-8B. DeepSeek utilized data generated by DeepSeek-R1, to fine-tune Llama-3.1-8B. This process, known as distillation (a subcatego
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
LOWContainer / deploy · priv.container · CWE-250, CWE-16
references/llms-txt.md:2420
--net=host \
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
references/llms-txt.md:9184
We can now save the finetuned model as a small 100MB file called a LoRA adapter like below. You can instead push to the Hugging Face hub as well if you want to upload your model! Remember to get a Hug
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
references/llms-txt.md:9379
You can save the finetuned model as a small 100MB file called a LoRA adapter like below. You can instead push to the Hugging Face hub as well if you want to upload your model! Remember to get a Huggin
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
references/llms-txt.md:11262
We can now save the finetuned model as a small 100MB file called a LoRA adapter like below. You can instead push to the Hugging Face hub as well if you want to upload your model! Remember to get a Hug
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
references/llms-txt.md:1331
-e "SSH_KEY=$(cat ~/.ssh/container_key.pub)"
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
references/llms-txt.md:4135
-e "SSH_KEY=$(cat ~/.ssh/container_key.pub)" \
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
references/llms-txt.md:4708
-e "SSH_KEY=$(cat ~/.ssh/container_key.pub)" \
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
references/llms-txt.md:9876
-e "SSH_KEY=$(cat ~/.ssh/container_key.pub)" \
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
references/llms-txt.md:11793
-e "SSH_KEY=$(cat ~/.ssh/container_key.pub)" \
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
references/llms-txt.md:36
Read more on running Llama 4 here: <https://docs.unsloth.ai/basics/tutorial-how-to-run-and-fine-tune-llama-4>
Why it matters. remote text is to be obeyed as instructions
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
references/llms-txt.md:3340
If you're looking to install Conda in a Linux environment, [read here](https://docs.anaconda.com/miniconda/), or run the below:
Why it matters. remote text is to be obeyed as instructions
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
references/llms-txt.md:188
curl -fsSL https://ollama.com/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
references/llms-txt.md:1263
curl -fsSL https://ollama.com/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
references/llms-txt.md:3543
curl -LsSf https://astral.sh/uv/install.sh | sh && source $HOME/.local/bin/env
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
references/llms-txt.md:3754
curl -fsSL https://ollama.com/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
references/llms-txt.md:3975
curl -fsSL https://ollama.com/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 5ff3ca429e5bfull audit observations/trust-audit/skill/foryourhealth111-pixel__unsloth.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-085ff3ca429e5bBLOCKD69first audit
06

Questions

What does the Unsloth skill do?

Intelligent Skill routing and workflow orchestration for AI agents — +21.12 pp reward, −29.6% tokens on SkillsBench with DeepSeekV4Flash-VE.

Is Unsloth safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What can Unsloth access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (5ff3ca429e5b), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement